Wikimedia Foundation logo

Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool

OpenAI agents tried to compromise a public note-taking tool, attempted to edit Wikipedia pages and possibly contributed to site disruptions earlier this year, according to a new statement from the Wikimedia Foundation.

The nonprofit released a detailed investigative report about a series of incidents involving OpenAI agents that repeatedly abused the site’s rules and took several unauthorized actions. 

The California-based foundation is best known for hosting and running Wikipedia — which has more than 67 million articles across 300 languages. It has become one of the most popular sources of information over the last decade, allowing people to make verified edits to pages.

The organization’s investigation found edits made to Wikipedia pages by OpenAI agents that were not published. The agents also made “potentially malicious edits” that were intended to misuse a citation tool “as a proxy for fetching data from remote services.”

Wikipedia does allow bots to make edits to pages when they are disclosed and approved by community editors, but those rules weren’t followed in this incident. 

Wikimedia also found two other issues tied to OpenAI agents, including unsuccessful attempts to compromise Etherpad — a note-taking tool the organization hosts as a community service.

“Agents unsuccessfully tried to use it to fetch data from other websites as a proxy. Other agents also likely operated by OpenAI took notes about their tasks, though this did not appear to turn into coordination,” Wikimedia said. The foundation noted that OpenAI’s agents have been seen compromising public platforms to communicate with one another.

Wikimedia added that agents operated by OpenAI also made millions of automated requests to access the knowledge on Wikimedia projects, crawled millions of pages and made hundreds of thousands of data queries to the site — potentially contributing to a partial outage of a Wikimedia service in May. 

OpenAI did not respond to requests for comment. Wikimedia said it began the investigation after recent reports found allegedly “rogue” AI agents tried to break into websites and other online services to use them for unrelated tasks. 

New reports continue to emerge weekly detailing the ways AI agents misuse platforms, breach government systems and access sensitive data.

At a Senate hearing last week, multiple members from both parties floated the idea that AI companies should be liable for the damage their agents cause. 

Drain on resources

Wikimedia said that the activity it observed could be tough for many web platforms to confront, given that they may not have the staff or funding to afford investigations or recovery efforts. 

“For a site like Wikipedia, agents might find and use security vulnerabilities or make misleading edits at scale. Wikipedia’s volunteer editors and the Wikimedia Foundation’s security teams have to detect and undo that activity,” the nonprofit said. 

Wikimedia’s investigation found no evidence that OpenAI agents used its sites to coordinate or steal information from the organization. 

But Wikimedia said it is concerned by what the investigation did find and expressed concern about the amount of effort it took to uncover the activity. 

The nonprofit said its employees have increasingly had to “clean up the mess left behind by AI agents” and now sees large bandwidth usage increases due to bot activity. 

Last week, researchers said OpenAI agents scraped data from more than 50 private and public sector organizations’ websites over a six-month period earlier this year.

Wikimedia said OpenAI needs to “acknowledge their responsibility to monitor and prevent these risks.” 

“AI companies are not doing enough to secure their systems and protect the public from the harm they cause. That burden is falling onto everyone else, including smaller organizations,” Wikimedia said. “At a minimum, their systems should operate in a way that non-profit website owners like us can easily identify, and choose how they interact with our services.”

In an interview on Monday, OpenAI CEO Sam Altman told Politico that the world “should accept some bad things happening for the benefits of this technology.”

Recorded Future
No previous article
No new articles
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.